Description
Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device initiated remote port-forward channel can be used to connect to the web management interface. Knowledge of authorization credentials to the management interface is required to perform any further actions.
Published: 2021-04-19
Score: 5.9 Medium
EPSS: 1.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-8398 Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device initiated remote port-forward channel can be used to connect to the web management interface. Knowledge of authorization credentials to the management interface is required to perform any further actions.
History

No history.

Subscriptions

Fibaro Home Center 2 Home Center 2 Firmware Home Center Lite Home Center Lite Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-17T00:42:24.901Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-20989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-19T14:15:11.570

Modified: 2024-11-21T05:47:20.583

Link: CVE-2021-20989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses